I keep getting a program called ProWsetup.exe trying to launch. how to stop

Note: Please do not post Personally Identifiable Information like email address, personal phone number, physical home address, product key etc.

Issue abstract: Unwanted “Prowsetup.exe” installer keeps popping up

Detailed description: I keep getting a popup appearing called “ProWsetup.exe”. I have not executed it, but have tried a full system scan and have ran Norton Power eraser too with the root kit scan turned on. It still pops up about once an hour or so. I can kill the popup in task manager but keeps coming back.
Any ideas how to stop this?

Product & version number: Norton 360

OS details: Windows 11 home

What is the error message you are seeing? none, just the popup

If you have any supporting screenshots, please add them:

You might have missed some add on to a genuine download you made that included this app. Try a second opinion scan with the free version of Malwarebytes. Malwarebytes concentrates on things that Norton does not.

Malwarebytes Antivirus, Anti-Malware, Privacy & Scam Protection

Thanks much for the suggestion. However, I tried MalwareBytes already and it did clean three files but the problem persists.

may be related: https://www.pwactechs.com/

may be related:
https://www.reddit.com/r/WindowsHelp/comments/1lu5r35/prow_setup_pop_up_wont_go_away/

https://www.reddit.com/r/WindowsHelp/comments/1hqo8zw/program_named_prow_file_compressor_appeared_on_my/

========================================

fwiw ~ my boiler plate reply

@donna_zelesky May I suggest you first, disconnect the computer from the Internet. Then boot Windows 11 into safe mode, here is how to do that:

Now that you are offline delete ALL files in the following locations on your C:\ drive:
C:\Users\You\AppData\Local\Temp
C:\Windows\Temp

Next: Delete ALL cookies and cache files from ALL browsers that are installed whether you use them or not. Clear everything.

Run another full scan with Malwarebytes if it will run in safe mode and reboot with the device still offline. Lets see if this issue returns.

SA

1 Like

fwiw ~ as test:


VirusTotal report: here


Details

Threat name: Script:SNH-gen [Drp]
Threat type: Dropper - This threat can secretly install other applications on your computer.
Status: Moved to Quarantine
Options: Report false detection
Detected by: Auto-Protect
On PC from: 7/10/25,
Last Used: 7/10/25,
Startup Item: No

Unknown
It is unknown how many users in the Norton Community have used this file.
Unknown
The file release is currently unknown
High
The file risk is high.


Activity
Path | Type | Status
C:\Sandbox\user\Default\user\current\AppData\Local\Temp\is-3U95U.tmp\dl_1.vbs | File | Repaired
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoWindowsUpdate | Registry value | Repaired

================================================

Thanks very much for your help. I did as you suggested so I will see if it reappears. I knew about deleting all in the one temp folder but not the other one so both are clean. I ran malware bytes in safe mode again nothing found. And the browsers are clean too. Thanks, and I will reply if it returns.

2 Likes

Great and thanks for the post back.

SA

@donna_zelesky Checking to see what your status is and can we assist further?

SA

All is well now. The help I received here was just great! Very knowledgeable people in here that is for sure! thanks a bunch for all the help with my virus problem!

Donna would you care to share with the forums what your solution was? Those having similar issues can then search for and find the solution you had. Thank you for the post-back, glad we could help in some way.

SA